<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MariaDB</title>
  <link>https://cvedaily.com/pages/tags/mariadb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mariadb.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MariaDB</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-48188 – An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48188</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48188</strong></p>
  <p>An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode.  This issue affects OTRS:     *  7.0.X   *  8.0.X   *  2023.X   *  2024.X   *  2025.X   *  2026…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43917 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43917</guid>
    <pubDate>Fri, 29 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43917</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware only verifies the user is authenticated - it does NOT enforce organization scoping. Each endpoint must individually verify the resource's org matches the session's activeOrganizationId. This affects the following endpoints: allByType, killProcess, and removeDeployment in deploym…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46446 – SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46446</guid>
    <pubDate>Thu, 14 May 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46446</strong></p>
  <p>SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47091 – Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk &lt;2.4.0p2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47091</guid>
    <pubDate>Wed, 13 May 2026 10:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47091</strong></p>
  <p>Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a local unprivileged user able to create a Windows service whose name matches 'MySQL' or 'MariaDB' (or with write access to a binary referenced by such a service) to execute arbitrary code in the context of the Checkmk agent service, which typically runs as SYSTEM.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40887 – Vendure is an open-source headless commerce platform. Starting in version 1.7.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40887</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40887</strong></p>
  <p>Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the dat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35549 – An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35549</guid>
    <pubDate>Fri, 03 Apr 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35549</strong></p>
  <p>An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32710 – MariaDB server is a community developed fork of MySQL server. An authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32710</guid>
    <pubDate>Fri, 20 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32710</strong></p>
  <p>MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These conditions require tight control over memory layout which is generally only attainable in a lab enviro…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3494 – In MariaDB server version through 11.8.5, when server audit plugin is enabled wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3494</guid>
    <pubDate>Tue, 03 Mar 2026 20:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3494</strong></p>
  <p>In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-778</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47761 – MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47761</guid>
    <pubDate>Thu, 15 Jan 2026 16:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47761</strong></p>
  <p>MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that allows authenticated users to modify service executable files in the MariaDB bin directory. Attackers can replace the mysqld.exe with a malicious executable, which will execute with system privileges when the computer restarts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22027 – CryptoLib provides a software-only solution using the CCSDS Space Data Link Secu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22027</guid>
    <pubDate>Sat, 10 Jan 2026 01:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22027</strong></p>
  <p>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the convert_hexstring_to_byte_array() function in the MariaDB SA interface writes decoded bytes into a caller-provided buffer without any capaci…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13699 – MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13699</guid>
    <pubDate>Tue, 23 Dec 2025 22:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13699</strong></p>
  <p>MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.  The specific flaw exists within the handling of view names.…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14758 – Incorrect configuration of replication security in the MariaDB component of the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14758</guid>
    <pubDate>Tue, 16 Dec 2025 01:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14758</strong></p>
  <p>Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including credentials</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10289 – The Filter &amp; Grids plugin for WordPress is vulnerable to SQL Injection via the '...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10289</guid>
    <pubDate>Sat, 13 Dec 2025 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10289</strong></p>
  <p>The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via the 'phrase' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used t…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67509 – Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67509</guid>
    <pubDate>Wed, 10 Dec 2025 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67509</strong></p>
  <p>Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass.  MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INT…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41076 – In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41076</guid>
    <pubDate>Thu, 20 Nov 2025 15:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41076</strong></p>
  <p>In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conf…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59681 – An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59681</guid>
    <pubDate>Wed, 01 Oct 2025 19:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59681</strong></p>
  <p>An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to these methods (on MySQL and MariaDB).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56404 – An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56404</guid>
    <pubDate>Wed, 10 Sep 2025 14:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56404</strong></p>
  <p>An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52971 – MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52971</guid>
    <pubDate>Sat, 08 Mar 2025 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52971</strong></p>
  <p>MariaDB Server 10.10 through 10.11.* and 11.0 through 11.4.* crashes in JOIN::fix_all_splittings_in_plan.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-1038</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52970 – MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52970</guid>
    <pubDate>Sat, 08 Mar 2025 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52970</strong></p>
  <p>MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, 11.0 through 11.0.*, and 11.1 through 11.4.* crashes in Item_direct_view_ref::derived_field_transformer_for_where.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-1038</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52969 – MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52969</guid>
    <pubDate>Sat, 08 Mar 2025 23:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52969</strong></p>
  <p>MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This may be related to make_aggr_tables_info and optimize_stage2.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-1038</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52968 – MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52968</guid>
    <pubDate>Sat, 08 Mar 2025 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52968</strong></p>
  <p>MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table crash.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-696</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27766 – An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27766</guid>
    <pubDate>Thu, 17 Oct 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27766</strong></p>
  <p>An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39593 – Insecure permissions in the sys_exec function of MariaDB v10.5 allows authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39593</guid>
    <pubDate>Thu, 17 Oct 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39593</strong></p>
  <p>Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26785 – MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26785</guid>
    <pubDate>Thu, 17 Oct 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26785</strong></p>
  <p>MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45308 – HedgeDoc is an open source, real-time, collaborative, markdown notes application...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45308</guid>
    <pubDate>Mon, 02 Sep 2024 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45308</strong></p>
  <p>HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed anymore and is effectively hidden by the new one. When the freeURL feature is enabled (by setting the `allowFreeURL` config option or the `C…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1289</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34693 – Improper Input Validation vulnerability in Apache Superset, allows for an authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34693</guid>
    <pubDate>Thu, 20 Jun 2024 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34693</strong></p>
  <p>Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL command that is able to read files from the serve…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32879 – Python Social Auth is a social authentication/registration mechanism. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32879</guid>
    <pubDate>Wed, 24 Apr 2024 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32879</strong></p>
  <p>Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affecte…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5456 – A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5456</guid>
    <pubDate>Tue, 05 Mar 2024 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5456</strong></p>
  <p>A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27295 – Directus is a real-time API and App dashboard for managing SQL database content...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27295</guid>
    <pubDate>Fri, 01 Mar 2024 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27295</strong></p>
  <p>Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar email address as the victim with a one or more characters changed to use accents. This is due to the fact that by default MySQL/MariaDB are configured fo…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24812 – Frappe is a full-stack web application framework that uses Python and MariaDB on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24812</guid>
    <pubDate>Wed, 07 Feb 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24812</strong></p>
  <p>Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to versions 14.59.0 and 15.5.0, portal pages are susceptible to Cross-Site Scripting (XSS) which can be used to inject malicious JS code if user clicks on a malicious link. This vulnerability has been patched in versions 14.59.0 and 15.5.0. No known…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52082 – Lychee is a free photo-management tool.  Prior to 5.0.2, Lychee is vulnerable to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52082</guid>
    <pubDate>Thu, 28 Dec 2023 16:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52082</strong></p>
  <p>Lychee is a free photo-management tool.  Prior to 5.0.2, Lychee is vulnerable to an SQL injection on any binding when using mysql/mariadb. This injection is only active for users with the `.env` settings set to DB_LOG_SQL=true and DB_LOG_SQL_EXPLAIN=true. The defaults settings of Lychee are safe.  The patch is provided on version 5.0.2.  To work around this issue, disable SQL EXPLAIN logging.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46127 – Frappe is a full-stack web application framework that uses Python and MariaDB on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46127</guid>
    <pubDate>Mon, 23 Oct 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46127</strong></p>
  <p>Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and an integrated client side library. A malicious Frappe user with desk access could create documents containing HTML payloads allowing HTML Injection. This vulnerability has been patched in version 14.49.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5157 – A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 456...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5157</guid>
    <pubDate>Wed, 27 Sep 2023 15:19:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5157</strong></p>
  <p>A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40354 – An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an enc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40354</guid>
    <pubDate>Mon, 14 Aug 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40354</strong></p>
  <p>An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26567 – Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26567</guid>
    <pubDate>Wed, 26 Apr 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26567</strong></p>
  <p>Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-47015 – MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47015</guid>
    <pubDate>Fri, 20 Jan 2023 19:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-47015</strong></p>
  <p>MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39267 – Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39267</guid>
    <pubDate>Wed, 19 Oct 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39267</strong></p>
  <p>Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39219 – Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39219</guid>
    <pubDate>Mon, 26 Sep 2022 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39219</strong></p>
  <p>Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are cur…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-38791 – In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38791</guid>
    <pubDate>Sat, 27 Aug 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-38791</strong></p>
  <p>In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32091 – MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32091</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32091</strong></p>
  <p>MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32089 – MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32089</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32089</strong></p>
  <p>MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32088 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32088</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32088</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32087 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32087</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32087</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32086 – MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32086</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32086</strong></p>
  <p>MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32085 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32085</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32085</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32084 – MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32084</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32084</strong></p>
  <p>MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32083 – MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32083</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32083</strong></p>
  <p>MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32082 – MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table-&gt;...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32082</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32082</strong></p>
  <p>MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32081 – MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32081</guid>
    <pubDate>Fri, 01 Jul 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32081</strong></p>
  <p>MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31624 – MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31624</guid>
    <pubDate>Wed, 25 May 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31624</strong></p>
  <p>MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31623 – MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31623</guid>
    <pubDate>Wed, 25 May 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31623</strong></p>
  <p>MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug an…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31622 – MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31622</guid>
    <pubDate>Wed, 25 May 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31622</strong></p>
  <p>MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31621 – MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31621</guid>
    <pubDate>Wed, 25 May 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31621</strong></p>
  <p>MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27457 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27457</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27457</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27456 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27456</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27456</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27455 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27455</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27455</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27452 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27452</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27452</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27451 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27451</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27451</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27449 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27449</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27449</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27448 – There is an Assertion failure in MariaDB Server v10.9 and below via 'node-&gt;pcur-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27448</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27448</strong></p>
  <p>There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27447 – MariaDB Server v10.9 and below was discovered to contain a use-after-free via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27447</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27447</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27446 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27446</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27446</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27445 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27445</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27445</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27444 – MariaDB Server v10.9 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27444</guid>
    <pubDate>Thu, 14 Apr 2022 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27444</strong></p>
  <p>MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27387 – MariaDB Server v10.7 and below was discovered to contain a global buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27387</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27387</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27386 – MariaDB Server v10.7 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27386</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27386</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27385 – An issue in the component Used_tables_and_const_cache::used_tables_and_const_cac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27385</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27385</strong></p>
  <p>An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27384 – An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27384</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27384</strong></p>
  <p>An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27383 – MariaDB Server v10.6 and below was discovered to contain an use-after-free in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27383</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27383</strong></p>
  <p>MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27382 – MariaDB Server v10.7 and below was discovered to contain a segmentation fault vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27382</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27382</strong></p>
  <p>MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27381 – An issue in the component Field::set_default of MariaDB Server v10.6 and below w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27381</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27381</strong></p>
  <p>An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27380 – An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27380</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27380</strong></p>
  <p>An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27379 – An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27379</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27379</strong></p>
  <p>An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27378 – An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27378</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27378</strong></p>
  <p>An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27377 – MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27377</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27377</strong></p>
  <p>MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27376 – MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27376</guid>
    <pubDate>Tue, 12 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27376</strong></p>
  <p>MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24052 – MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24052</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24052</strong></p>
  <p>MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-suppli…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24051 – MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24051</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24051</strong></p>
  <p>MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24050 – MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24050</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24050</strong></p>
  <p>MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24048 – MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24048</guid>
    <pubDate>Fri, 18 Feb 2022 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24048</strong></p>
  <p>MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-suppl…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-46669 – MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46669</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-46669</strong></p>
  <p>MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46668 – MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46668</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46668</strong></p>
  <p>MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46667 – MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46667</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46667</strong></p>
  <p>MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46666 – MariaDB before 10.6.2 allows an application crash because of mishandling of a pu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46666</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46666</strong></p>
  <p>MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46665 – MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46665</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46665</strong></p>
  <p>MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46664 – MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46664</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46664</strong></p>
  <p>MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46663 – MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46663</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46663</strong></p>
  <p>MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46662 – MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46662</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46662</strong></p>
  <p>MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with a nested subquery.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46661 – MariaDB through 10.5.9 allows an application crash in find_field_in_tables and f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46661</guid>
    <pubDate>Tue, 01 Feb 2022 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46661</strong></p>
  <p>MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46659 – MariaDB before 10.7.2 allows an application crash because it does not recognize ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46659</guid>
    <pubDate>Sat, 29 Jan 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46659</strong></p>
  <p>MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46658 – save_window_function_values in MariaDB before 10.6.3 allows an application crash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46658</guid>
    <pubDate>Sat, 29 Jan 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46658</strong></p>
  <p>save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_window_func=true for a subquery.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46657 – get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46657</guid>
    <pubDate>Sat, 29 Jan 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46657</strong></p>
  <p>get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21664 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21664</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21664</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 4.1.34. We strongly recommend that you…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21663 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21663</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21663</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly r…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21662 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21662</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21662</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go ba…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21661 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21661</guid>
    <pubDate>Thu, 06 Jan 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21661</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37.…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41679 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41679</guid>
    <pubDate>Tue, 30 Nov 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41679</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41678 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41678</guid>
    <pubDate>Tue, 30 Nov 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41678</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41677 – A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or Mar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41677</guid>
    <pubDate>Tue, 30 Nov 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41677</strong></p>
  <p>A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-39203 – WordPress is a free and open-source content management system written in PHP and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39203</guid>
    <pubDate>Thu, 09 Sep 2021 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-39203</strong></p>
  <p>WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 beta during the testing period. It's fixed in the final 5.8 release.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39203">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
